WebKit’s IP Leak: When Apple’s Privacy Story Breaks Down
The iCloud Private Relay vulnerability is a set of WebKit flaws that allow websites to bypass Apple’s proxy protections and see a user’s real IP address and DNS information, exposing iPhone and Mac users even when they believe their browsing is protected by Private Relay or privacy-focused browsers. That should be a gut punch for anyone who trusted Apple’s narrative that its ecosystem offers superior privacy by design. These are not obscure edge cases; they strike at the browser engine that every iOS browser is forced to use. Three distinct bugs—DNS prefetching, WebAuthn Related Origin Requests, and WebTransport—create a WebKit IP leak that bypasses application-level proxies and iCloud Private Relay, leaving the real IP address exposed. This is an information leak, not a device compromise, but that distinction is cold comfort when your anonymity is the promise you thought you bought.

How Passkeys and WebKit Quietly Reveal Your Real IP Address
The most troubling piece of this iPhone privacy flaw is how ordinary passkey sign-ins can pierce Private Relay’s shield. WebAuthn Related Origin Requests were introduced to streamline passkey validation across related domains, but they do it by handing the job to the operating system’s credential service instead of the browser. Because that traffic never enters the Private Relay proxy route, the destination server receives your device’s real IP address. A malicious operator can build a page around a passkey check and quietly log every visitor’s address, no malware, downloads, or passwords required. Apple has spent years marketing passkeys and Private Relay as privacy-friendly, but here they combine into a perfect trap. The user sees a familiar passkey prompt and assumes privacy is intact, while the underlying WebKit behavior undermines the core promise of iCloud Private Relay.
Privacy Browsers on iOS Are Caught in the Same Net
If you assumed a privacy browser or Tor-based app on iOS would save you, the WebKit IP leak proves otherwise. Apple mandates that every iOS browser use WebKit, which means a vulnerability at this layer instantly becomes a single point of failure for nearly the entire platform. Researchers found that even Onion Browser, which uses the Tor anonymity network, inherits these leaks through WebKit’s behavior. DNS prefetching resolves hostnames via the device’s normal DNS path, exposing real DNS servers, while WebTransport opens raw HTTP/3 connections that ignore proxy rules altogether. The result: privacy browsers and iCloud Private Relay are leaking your IP and DNS in ways that tracking sites can harvest using simple HTML tags or passive WebAuthn requests, without explicit user interaction. Onion Browser’s Lockdown Mode can disable WebTransport, but default configurations remain vulnerable, underscoring that app-level privacy design cannot fully outrun WebKit’s flaws.
This Is an Information Leak, Not a Hack — But It Still Matters
It is tempting to downplay these bugs because they do not install malware or take over accounts. The sources are clear: this case is an information leak, and there is no evidence that devices were infected or accounts were compromised. But privacy threats are built on information, not drama. An IP address can reveal your network provider and approximate location, and can be combined with other data for profiling, stalking, fraud, or targeted attacks. WebTransport QUIC connections and WebAuthn requests bypass application proxy settings, so iCloud Private Relay and proxy browsers cannot see or protect that traffic. Meanwhile, DNS prefetching exposes your real DNS path, feeding trackers yet another data point. According to the cybersecurity researchers who built the proof-of-concept site, “three WebKit privacy leaks expose users’ real IP addresses on iPhone and Mac, even when they use a proxy browser or iCloud Private Relay.”
What You Should Do Now—and Why Private Relay Isn’t Enough
The immediate lesson is harsh: iCloud Private Relay is not a complete privacy solution, and users who need stronger anonymity should stop treating it as a replacement for system-wide tools. Until Apple ships fixes, you should be wary of unfamiliar sites that request or imitate passkey support, especially for sensitive browsing. Use a system-wide VPN; because VPNs operate at the system level, they remain unaffected by these leaks and keep traffic encrypted so WebKit cannot bypass them. For maximum protection, combine a VPN with strict browser privacy settings, creating layered defenses around your traffic. You can test whether your setup is leaking by visiting the connection exposure webpage built by the researchers. Apple has said it is investigating and has been formally notified of the vulnerabilities, but it has not announced any timeline for fixes. Related reporting on iCloud data risks shows why privacy features should be judged by their limits, not their marketing. The smart move now is to assume Partial Relay, not Private Relay, and bolster your defenses accordingly.






